• 0 Posts
  • 41 Comments
Joined 1 year ago
cake
Cake day: June 17th, 2023

help-circle


  • Totally agreed, but there are pros and cons.

    File - harder to steal but once stolen hacker can bruteforce it as much as it wants. Web service - with proper rate limits (and additional IP whitelist so you can only sync on VPN/local network) - its harder to bruteforce. (But yes, you (sometimes) have also full copy locally in the local client, but …)

    If it was only for me I probably would also go with KeePass as you will not update the same db at the same time, but with with multiple users it’s getting unmanageable.

    I just got triggered as those CVEs are not that bad due to the nature that the app encrypts stuff on the client side so web server is more like shared file storage, while your answer suggested to switch to a solution that doesn’t work for a lot of people (as we already tried that).





  • Just having btrfs is not enough, you need to have automatic snapshots (or do them manually) before doing updates and configured grub to allow you to rollback.

    Personally, I’m to lazy to configure stuff like that, I rather just pick my Vetroy USB from backpack, boot into live image and just fix it (while learning something/new interesting) than spend time preventing something that might never happen to me :)


  • It first downloads all packages from net, then it proceed totally offline starting by verifying downloaded files, signatures, extracting new packages and finally rebuilding initramfs.

    Because arch is replacing the kernel and inittamfs in-place there is a chance that it will not boot if interrupted.

    This issue was long resolved on other distro.

    One way to mitigate it is by having multiple kernels (like LTS or hardened) that you can always pick in grub if the main one fail.





  • Just because you send me malware after some text I wanted to read (in http response), don’t give you rights to force me to execute the malware.

    Just because I have your book (or page) and look at part of it doesn’t give you the right to force me to read it in full or dictate how I’m reading it.

    I have every right to reveal/read only part of the book/page. We didn’t sign any agreement, if you want me to first look at the part you want to or agree to some license nothing stopping you to do, stuff like paywall or subscription exists…









  • Over all I upvote posts if its something I would like to know about.

    In this case its good to know that there was some limit issue that (as on the page say) is already resolved.

    If it was intentionally done or not we will never know, but its good to know if it would happen again that there is some limit.

    I upvote because:

    • even if it was some wrongly implemented limit in this case, the shadow banning/hidding posts (or like in this case blocking follow) will happen in the future on all large platforms, it’s human nature to abuse it if you can get away with it
    • I dont like big central platforms, I rather would like to have a transparent/open platform but I know it will never happen as servers costs money and people like “free” and convenient stuff so platforma will keep monetizing people activity
    • if it could be even slightly true I rather have as many (affected) people know about it that there was an issue with follow and now it is resolved so they can retry to follow